Splunk SOAR Certified Automation Developer Exam Guide
The Splunk SOAR Certified Automation Developer exam validates professional-level ability to configure a SOAR server, integrate Splunk, and plan, build, and debug playbooks. It is intended for candidates working with SOAR administration and automation development, including people who know the credential by its former name, Splunk Phantom Certified Admin. This guide helps you decide whether the legacy exam matches your goal, identify the skills to study, and sequence practice before you schedule an attempt.
What does this certification validate?
This certification is about operating and extending a Splunk SOAR environment, not simply recognizing security terminology. Splunk associates it with SOAR-server installation and configuration, Splunk integration, and the planning, design, creation, and debugging of playbooks. The exam is classified by Splunk as professional-level and is listed as a legacy certification.
The credential was formerly referred to as Splunk Phantom Certified Admin. That earlier name matters when searching for older training references, internal role descriptions, or study material. Treat references to Phantom as historical terminology, then map the material back to the current Splunk SOAR domain names in the official blueprint.
A sensible candidate profile is an administrator, automation developer, or security operations practitioner who needs to understand how SOAR is deployed, configured, connected to other Splunk capabilities, and used to execute repeatable response workflows. The official sources do not state that a particular job title is required, so use the skill coverage rather than a title as your eligibility test.
The exam does not have a prerequisite certification or prerequisite course. That removes a formal entry barrier, but it does not remove the need to understand the product areas in the blueprint. If your experience is limited to consuming playbook results, plan additional environment practice before paying for an attempt.
Should you schedule a legacy exam?
Confirm the exam’s status and relevance on Splunk’s official certification page before scheduling. Splunk lists the Splunk SOAR Certified Automation Developer as a legacy certification, and the blueprint states that legacy exam content will no longer be actively maintained or updated to reflect product changes or releases. This makes version alignment a central scheduling decision, not a footnote.
The practical choice is straightforward: schedule only when the credential still serves your employer, project, or career plan and the available blueprint matches the SOAR environment you are preparing for. If your objective is a current certification path, compare Splunk’s active certification offerings before committing to this legacy credential.
Do not treat an old course outline, third-party question bank, or former Phantom reference as proof that it reflects the assessed content. Use the official blueprint as the controlling study scope, and check the certification page for the current scheduling route and status. Where the official pages conflict with older catalogue information, the current official page should guide your decision.
Splunk’s certification page lists a price of $130 USD per exam attempt, states that the exam is delivered by Pearson VUE, and describes the format as multiple choice. The same page lists the exam length as 60 minutes. Verify the live registration details before purchase because scheduling information can change.
What are the exam delivery details?
The evidenced delivery details are a multiple-choice exam with 45 questions and a listed length of 60 minutes. The blueprint clarifies that the 60-minute total exam time includes three minutes to review the exam agreement. Use those facts to plan a measured response pace rather than assuming that all time is available for answering questions.
The official certification page identifies Pearson VUE as the exam provider. It also lists the price as $130 USD per exam attempt. The supplied sources do not establish every current delivery option, location, language, identification rule, rescheduling condition, or result policy, so obtain those details from the Pearson VUE scheduling flow and Splunk’s current exam information before booking.
A useful preparation exercise is to work through representative, self-written scenarios under a strict time limit. Do not use recalled or leaked exam questions. Instead, create questions from the published domains: for example, decide which playbook block belongs in a workflow, identify a configuration dependency, or explain how an action result should be handled.
Keep the three-minute agreement review in your scheduling arithmetic. The remaining exam time is not a promise that every question will require equal effort; it is a reason to avoid spending too long reconstructing one uncertain answer. Mark difficult items according to the rules presented by the test provider, then return to them if permitted.
Which skills does the blueprint measure?
The blueprint spans environment setup, SOAR operation, and automation construction. It covers deployment, installation, initial configuration, user management, apps, assets, and playbooks, then extends into analyst-queue use, investigation-page operations, case management, workbooks, customizations, and system maintenance.
For automation development, the blueprint includes automation best practices, playbook capabilities, available app actions, and the I2A2 design methodology. It also names visual playbook editing, decision and filter blocks, join options, user interaction during execution, format blocks, and action-result structure. These topics should become the backbone of your study notes and lab checklist.
The supplied research does not provide percentage weights for the domains. Do not invent a weighted priority or compare unlabeled percentages. In the absence of published weights here, prioritize by both breadth and personal weakness: first cover all named areas, then spend extra practice time on the areas where you cannot explain the execution flow or troubleshoot a configuration without notes.
A useful distinction is between knowing where a feature exists and knowing how it affects an investigation. The blueprint’s inclusion of analyst queues, investigation pages, case management, and workbooks means that administration and automation should be studied in operational context. A playbook is not an isolated diagram; it participates in a workflow involving data, actions, results, and users.
Environment and administration skills
Study deployment, installation, initial configuration, user management, apps, assets, and system maintenance as connected responsibilities. Build a dependency map: what must exist before an app action can run, how an asset relates to an app, which users interact with the system, and where maintenance affects reliable operation. The blueprint names these areas, but it does not prescribe a single lab design.
Your notes should separate initial setup from ongoing administration. Initial configuration concerns making the environment usable; maintenance concerns keeping it serviceable and aligned with operational needs. This separation helps prevent a common study error: memorizing isolated menu locations without understanding which configuration stage a task belongs to.
Review the role of apps and assets in the action path. A candidate should be able to reason from a desired response step to the supporting integration and configured target, then identify what would prevent that action from producing a useful result. Use documentation and a permitted practice environment rather than attempting actions against production systems.
Investigation and case workflow skills
The blueprint covers analyst-queue use, investigation-page operations, case management, workbooks, customizations, and system maintenance. Study these as the human and operational layer around automation. For each area, write down the purpose of the view or object, the information an analyst needs, and how the item relates to an investigation’s progress.
A strong revision method is to trace one hypothetical incident from intake through investigation and case handling. At each stage, ask what an analyst would inspect, what information a playbook might add, what requires a user decision, and what should remain visible for later review. This is a practice scenario, not a prediction of live exam content.
Do not over-focus on playbook construction while ignoring analyst-facing operations. A developer who can draw a workflow but cannot explain how an analyst uses the investigation page or manages the resulting case has left a significant portion of the published scope uncovered.
Playbook design and debugging skills
The blueprint specifically names visual playbook editing, decision and filter blocks, join options, user interaction during execution, format blocks, and action-result structure. Study each feature by asking what data enters it, what it produces, and how the next step behaves when the expected result is missing, empty, or unsuccessful.
The I2A2 design methodology is also included in the blueprint. Learn its stages from the official material you are using, then apply the method to a small response objective before expanding it. The point of practice is to make design decisions traceable: define the intended outcome, identify the needed inputs and actions, and plan how the result will be checked and used.
For debugging practice, deliberately create a workflow with a bad assumption. Examples include an unavailable action dependency, an unexpected result structure, a branch that does not receive the required value, or a join that waits for an inappropriate set of paths. Diagnose the failure from the execution flow and result data, then record the correction and the reason for it.
Automation best practices should be studied alongside capabilities, not after them. A workflow that technically runs may still be difficult to read, difficult to maintain, or unclear to an analyst. Use descriptive names, explicit branching logic, and deliberate handling of action results as practical study standards; these are recommendations for practice, not additional official exam requirements.
How should you prepare without overfitting to questions?
Build preparation around the official blueprint, product practice, and explanation-based review. The objective is to answer a new scenario by reasoning about configuration, workflow, and results. Memorizing answer patterns from dumps or leaked material is not a reliable preparation method and does not demonstrate the capability the certification is intended to assess.
Start with a coverage inventory. Copy each named topic from the blueprint into a checklist and label it unfamiliar, familiar, or demonstrable. “Demonstrable” should mean that you can describe the purpose, configure or use the feature in an appropriate practice setting, and explain a likely failure path without relying on a memorized phrase.
Use Splunk’s official learning-path and certification resources to locate relevant study material. The supplied sources do not identify a single required course for this exam, and the track document confirms that there is no prerequisite course. Choose learning resources that directly map to the blueprint rather than assuming that a general Splunk course covers SOAR automation in sufficient depth.
Use Splunk Lantern’s SOAR help material as a navigation point for official assistance and product guidance. The supplied Lantern facts also state that most customers have OnDemand Services included as part of their license purchase, but those services expire at the end of each quarter. If you rely on that assistance, confirm your own entitlement and expiry with the relevant account or service information; do not assume it applies to every learner or lab.
A study sequence that reduces rework
Learn the platform context before constructing complex playbooks. Begin with deployment, installation, initial configuration, users, apps, and assets. Then move to analyst queues, investigation pages, cases, workbooks, customizations, and maintenance. Finish with playbook design, blocks, actions, interaction, formatting, results, best practices, and debugging. This sequence follows dependencies rather than treating every topic as a separate vocabulary list.
The sequence is a recommendation, not a Splunk-mandated course order. Adjust it if your work experience is stronger in administration or development, but preserve the dependency logic. Understanding what an action needs makes it easier to understand why a playbook fails; understanding the analyst workflow makes it easier to judge whether an automation is useful.
After each study block, write a short explanation from memory and then verify it against official material. If the explanation names a feature but cannot describe its input, output, dependency, or operational purpose, classify the topic as familiar rather than demonstrable and return it to the lab list.
Practice tasks for a permitted lab
Use a safe, authorized SOAR environment to construct small workflows rather than attempting to reproduce a large production solution. Begin with a simple action path, add a decision or filter, introduce a join, format a value, and inspect the resulting data. Then add a user interaction step and document what the analyst must do before execution can continue.
Practice app and asset reasoning separately from interface navigation. For each action you study, record the integration it belongs to, the asset or target it needs, the input it consumes, and the result structure you expect. If your environment does not contain a particular integration, use official documentation to learn the concept and mark the hands-on gap honestly.
Create a debugging worksheet with four columns: intended behavior, observed result, likely boundary or dependency, and correction. This forces you to distinguish a design error from a configuration error and a result-handling error. It also produces a compact revision tool for the final review.
Do not use production credentials, real incident data, or unapproved integrations for exam practice. The official sources establish the subject areas, not permission to test against operational systems. Keep practice isolated and follow your organization’s security and change-control rules.
How to make review questions useful
Write questions that test decisions rather than labels. A useful question describes a response objective and asks which configuration, block, action, or result-handling approach fits it. Your answer notes should explain why the alternatives do not fit. This method is more valuable than copying a phrase and associating it with a letter choice.
Mix administration and automation in the same review session. For example, begin with an app or asset dependency, continue into a playbook action, and finish by interpreting the action result in an investigation workflow. These combinations reflect the connected scope named by the blueprint without pretending to recreate the live exam.
Keep a separate error log. Record the topic, the mistaken assumption, the official source used to correct it, and the verification task you will perform. Revisit errors by category: environment setup, analyst workflow, visual editing, branching, joins, user interaction, formatting, action results, and debugging.
Avoid unsupported certainty about topics that the supplied sources do not detail. If the blueprint names a capability but the available material does not define every behavior, study the official documentation and phrase your notes around verified behavior. Do not fill gaps with invented limits, versions, question predictions, or claims about what will appear.
What mistakes can derail preparation?
The most damaging mistakes are scope errors: preparing for a current product release without checking the legacy status, studying only playbook blocks, or relying on material that is not mapped to the official blueprint. Correct these by verifying the credential first, building a complete topic inventory, and testing whether each note explains an operational decision.
A second mistake is confusing recognition with competence. Being able to define a filter or action does not prove that you can select it in a workflow, supply its dependencies, interpret its result, or debug the next step. Convert every definition into a small practice task or a written scenario with an explanation.
A third mistake is neglecting human workflow. Analyst queues, investigation pages, case management, and workbooks are explicitly covered. A study plan made entirely of development exercises leaves out how SOAR supports investigation and how automation interacts with users.
A fourth mistake is treating the exam timer as a reason to rush all preparation. The official blueprint specifies 45 questions, and the listed 60-minute total includes three minutes for the exam agreement. Use timed review near the end, but spend earlier sessions building accurate reasoning and correcting recurring errors.
Finally, do not schedule based on an assumed active roadmap. Splunk identifies this certification as legacy and says its legacy exam content will no longer be actively maintained or updated for product changes or releases. Verify that the credential is still the one your intended employer or project recognizes before using the published price or delivery information to make a purchase decision.
A practical final review roadmap
A focused final review should end with evidence of coverage, not a longer pile of notes. Confirm that you can explain every blueprint area, complete a small authorized playbook exercise, interpret action results, and identify configuration or design causes of failure. Then verify the live certification and Pearson VUE details before scheduling.
In the first stage, establish the decision to pursue the credential. Read the official certification page and blueprint, note the legacy designation, and confirm that the former Phantom terminology in older material refers to the same track. Check that the certification’s purpose still matches your goal and that the stated $130 USD per exam attempt is acceptable before proceeding.
In the second stage, close environment gaps. Review deployment, installation, initial configuration, user management, apps, assets, and system maintenance. Create a one-page dependency map that connects an intended action to its app, asset, user context, and expected result. Mark any item that you have only read about for additional verification.
In the third stage, rehearse the analyst path. Walk through analyst-queue use, investigation-page operations, case management, workbooks, and customizations. Explain where automation supports the workflow and where user interaction or review remains important. Keep the scenario synthetic and authorized; it is a reasoning exercise, not a reconstruction of exam content.
In the fourth stage, build and inspect small playbooks. Include visual editing, a decision or filter, a join choice, formatting, user interaction, and action-result handling across separate exercises. Apply the I2A2 methodology and automation best practices from the official blueprint material. For every exercise, write the expected result and one plausible failure mode.
In the final stage, perform a timed self-check using original questions. The official exam format is multiple choice, but your review should require written reasoning before you view any options. Review the error log, not just the questions you answered correctly. Stop adding new topics when the remaining weakness is clearly identified and schedule only after confirming current registration information.
What should you do next?
Your next action should be a status-and-scope check, not a purchase. Open the official certification page and test blueprint, confirm that the legacy credential remains appropriate for your objective, and build a checklist from the named domains. After that, choose an authorized practice environment and schedule only when configuration, analyst workflow, playbook construction, and debugging are all represented in your review.
Use Splunk’s official certification and learning-path pages to investigate available education options. Use the SOAR help resource when you need product guidance or assistance information, and confirm any service entitlement or expiry that applies to your organization. Before booking, verify the live price, provider instructions, delivery choices, and any rules that are not stated in the supplied research.
Keep this guide as a planning aid, but let the current official blueprint control your scope. Because Splunk says the legacy content is not actively maintained for product changes or releases, version and credential relevance deserve a final check immediately before scheduling. That check protects you from investing preparation time in a certification that no longer serves the outcome you need.
Conclusion
The best preparation decision for this exam is to verify relevance first, then study the full SOAR workflow rather than memorizing isolated terms. Use the blueprint to cover administration, analyst operations, playbook design, and debugging; use authorized practice to connect those areas; and use original scenario questions to test reasoning. Confirm current certification and Pearson VUE details before committing to the legacy exam.
Related exams
- SPLK-1004 exam — Splunk Core Certified Advanced Power User Exam
- SPLK-1005 exam — Splunk Cloud Certified Admin
- SPLK-4001 exam — Splunk O11y Cloud Certified Metrics User Exam